瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 backdoor.codbot.ee/backdoor.codbot.em ....怎么杀?

1   1  /  1  页   跳转

backdoor.codbot.ee/backdoor.codbot.em ....怎么杀?

backdoor.codbot.ee/backdoor.codbot.em ....怎么杀?

中毒的症状是在 winnt/system32/下面 老有莫明奇妙的文件 例如 aaa.exe bbb.exe hhh.exe uuu.exe等等的 有时候瑞行监控能察到他,有时候就不行,另外如果瑞星没查到的话 过段时间system32目录下面就会出现 spsys.exe 这样的文件,他会打开很多端口等待建立。

瑞星好像只能偶尔查杀,有人知道怎样能彻底查杀他么???
最后编辑2006-01-20 11:53:30
分享到:
gototop
 

这是我的

HijackThis_815汉化版扫描日志 V1.99.1
保存于      11:52:09, 日期 2006-1-20
操作系统:  Windows 2000 SP4 (WinNT 5.00.2195)
浏览器:    Internet Explorer v6.00 SP1 (6.00.2800.1106)

当前运行的进程:         
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\rising\Rav\CCenter.exe
C:\Program Files\rising\Rav\Ravmond.exe
C:\WINNT\System32\svchost.exe
d:\IMail\FINGRD32.exe
d:\IMail\ILDAP.exe
d:\IMail\IMAP4D32.exe
d:\IMail\IMonitor.exe
d:\IMail\IWebCal.exe
d:\IMail\iwebmsg.exe
C:\WINNT\System32\llssrv.exe
C:\PROGRA~1\MICROS~2\MSSQL\binn\sqlservr.exe
d:\IMail\POP3D32.exe
d:\IMail\PSERVE.exe
d:\IMail\queuemgr.exe
C:\Program Files\Serv-U\ServUDaemon.exe
d:\IMail\smtpd32.exe
d:\IMail\SYSLOGD.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\lserver.exe
d:\IMail\WHOISD32.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\rdpclip.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Wom\WinMem.exe
C:\Program Files\rising\Rav\RavTask.exe
C:\Program Files\rising\Rav\Ravmon.exe
C:\WINNT\system32\ctfmon.exe
C:\WINNT\system32\logon.scr
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\system32\taskmgr.exe
C:\Program Files\Alexa Toolbar\Iparmors\Iparmor.exe
C:\Program Files\rising\Rav\RavStore.exe
F:\bkws\HijackThis1991zww.exe

O2 - BHO: Microsoft Java Class - {6E28339B-7A2A-47B6-AEB2-46BA53782379} - C:\WINNT\system32\dllcache\java.dll (file missing)
O2 - BHO: AlxTB BHO - {F1FABE79-25FC-46de-8C5A-2C6DB9D64333} - C:\WINNT\system32\AlxTB1.dll
O3 - IE工具栏增项: Alexa - {3CEFF6CD-6F08-4e4d-BCCD-FF7415288C3B} - C:\WINNT\system32\SHDOCVW.DLL
O4 - 启动项HKLM\\Run: [Windows内存整理] C:\Program Files\Wom\WinMem.exe
O4 - 启动项HKLM\\Run: [RavTask] "C:\Program Files\rising\Rav\RavTask.exe" -system
O4 - 启动项HKLM\\Run: [iparmor] C:\Program Files\Alexa Toolbar\Iparmors\Iparmor.exe mini
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - IE右键菜单中的新增项目: Alexa Web Search - http://client.alexa.com/holiday/script/actions/search.htm
O8 - IE右键菜单中的新增项目: Get Alexa Data - http://client.alexa.com/holiday/script/actions/sitedata.htm
O8 - IE右键菜单中的新增项目: Mail to a Friend... - http://client.alexa.com/holiday/script/actions/mailto.htm
O8 - IE右键菜单中的新增项目: See Related Links - http://client.alexa.com/holiday/script/actions/related.htm
O8 - IE右键菜单中的新增项目: Write a Review... - http://client.alexa.com/holiday/script/actions/review.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载 - D:\PROGRA~1\FlashGet\jc_link.htm
O8 - IE右键菜单中的新增项目: 使用网际快车下载全部链接 - D:\PROGRA~1\FlashGet\jc_all.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125023325281
O20 - AppInit_DLLs: APIHookDll.dll
O23 - NT 服务: IMail FINGER Server (FINGRD32) - Ipswitch, Inc.  - d:\IMail\FINGRD32.exe
O23 - NT 服务: IMail LDAP Server (ILDAP) - Ipswitch, Inc.  - d:\IMail\ILDAP.exe
O23 - NT 服务: IMail IMAP4 Server (IMAP4D32) - Ipswitch, Inc.  - d:\IMail\IMAP4D32.exe
O23 - NT 服务: IMail Monitor Service (IMonitor) - Ipswitch, Inc.  - d:\IMail\IMonitor.exe
O23 - NT 服务: IMail Web Calendar Service (IWebCal) - Ipswitch, Inc.  - d:\IMail\IWebCal.exe
O23 - NT 服务: IMail Web Service (IWEBMSG) - Ipswitch, Inc.  - d:\IMail\iwebmsg.exe
O23 - NT 服务: IMail POP3 Server (POP3D32) - Ipswitch, Inc.  - d:\IMail\POP3D32.exe
O23 - NT 服务: IMail PWD Server (PSERVE) - Ipswitch, Inc.  - d:\IMail\PSERVE.exe
O23 - NT 服务: IMail Queue Manager Service (QueueMgr) - Ipswitch, Inc.  - d:\IMail\queuemgr.exe
O23 - NT 服务: Rising Process Communication Center (RsCCenter) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\CCenter.exe
O23 - NT 服务: RsRavMon Service (RsRavMon) - Beijing Rising Technology Co., Ltd. - C:\Program Files\rising\Rav\Ravmond.exe
O23 - NT 服务: Serv-U FTP 服务器 (Serv-U) - Cat Soft - C:\Program Files\Serv-U\ServUDaemon.exe
O23 - NT 服务: IMail SMTP Server (SMTPD32) - Ipswitch, Inc.  - d:\IMail\smtpd32.exe
O23 - NT 服务: IMail Sys Logger Service (SYSLOGD) - Ipswitch, Inc.  - d:\IMail\SYSLOGD.exe
O23 - NT 服务: IMail WHOIS Server (WHOISD32) - Ipswitch, Inc.  - d:\IMail\WHOISD32.exe

gototop
 
1   1  /  1  页   跳转
页面顶部
Powered by Discuz!NT